ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 405bReducing identity fraud

submitted 8 years ago by Pub. L. 115-174 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 1,179 words · no verdicts yet

in plain englishAI-generated · not legal advice

This law lets the Social Security Administration help stop synthetic identity fraud. Financial institutions can check a name, Social Security number, and birth date against SSA records with consent. Users pay fees to cover the program's costs.

(a) Purpose. This section aims to cut down on synthetic identity fraud (fraud that combines real and fake information to invent a fake identity), which especially hurts vulnerable people like minors and recent immigrants. It does this by letting "permitted entities" check "fraud protection data" against a database the Commissioner keeps, once the consumer has given electronic consent. (b) Definitions. "Commissioner" means the Commissioner of the Social Security Administration. "Financial institution" has the meaning given in section 509 of the Gramm-Leach-Bliley Act. "Fraud protection data" means, together: a person's name, their Social Security number, and their date of birth. "Permitted entity" means a financial institution, or a service provider, subsidiary, affiliate, agent, subcontractor, or assignee of one. (c) Efficiency. The Commissioner must study whether an existing database (or similar resource) from before May 24, 2018, can be adjusted to meet this section's goals and the requirements in subsection (d). The Commissioner must then make those changes — or build a new database or resource — so those requirements are met. (d) Protection of Vulnerable Consumers. The database or resource must: (1) compare the fraud protection data submitted in a request against what the Commissioner has on file, to confirm or not confirm it's accurate; (2) be able to scale up to handle expected request volumes, with reasonably reliable uptime; and (3) let permitted entities submit either (A) single real-time electronic requests with immediate machine-to-machine answers, or (B) batches of requests, answered electronically within a reasonable time — no more than 24 hours. (e) Certification Required. Before confirming any fraud protection data for a permitted entity, the Commissioner must get a signed certification from that entity, no more than 2 years old, stating: (1) it is a permitted entity; (2) it complies with this section; (3) it complies, and will keep complying, with the privacy and data-security rules in title V of the Gramm-Leach-Bliley Act, for information it gets from the Commissioner; and (4) it will keep records proving its compliance for at least 2 years. (f) Consumer Consent. (1) A permitted entity may only submit a request if: (A) the individual gave written (including electronic) consent, and (B) the request relates to a credit transaction or a situation described in section 1681b of title 15. (2) To use electronic consent, the entity must get the person's electronic signature, as defined in section 7006 of title 15. (3) No other law — including the Privacy Act (section 552a of title 5) — can block the use of electronic consent for this purpose, or for other consent-based checks the Commissioner allows. (g) Compliance and Enforcement. (1) The Commissioner may audit and monitor permitted entities, to make sure the database is used properly and to catch fraud or misuse, and may cut off service to any entity that blocks these audits. (2) Violations of this section, or of an entity's certification, are enforced the way section 505(a) of the Gramm-Leach-Bliley Act enforces violations — by the same agencies listed there. If an audit uncovers a violation, the Commissioner must send the relevant information to the right enforcement agency. (h) Recovery of Costs. (1) All money spent to run this program must be fully recovered from the entities that use the database — through advance payments, reimbursements, user fees, or similar means, set by the Commissioner. That recovered money goes into the Social Security Administration's account and can be used, without a yearly time limit, to run this program. The Commissioner sets and periodically adjusts the prices charged, to make sure they always cover the full cost. (2) The Commissioner cannot start building a verification system until at least 50% of the program's start-up costs have been collected. (3) The Commissioner may use funds set aside for information-technology modernization to help build this system. (4) The Commissioner must report each year to the House Ways and Means Committee and the Senate Finance Committee on the SSA's indirect costs from running this program.
the actual law source: uscode.house.gov ↗public domain
(a) Purpose

The purpose of this section is to reduce the prevalence of synthetic identity fraud, which disproportionally affects vulnerable populations, such as minors and recent immigrants, by facilitating the validation by permitted entities of fraud protection data, pursuant to electronically received consumer consent, through use of a database maintained by the Commissioner.

(b) Definitions

In this section:

(1) Commissioner

The term “Commissioner” means the Commissioner of the Social Security Administration.

(2) Financial institution

The term “financial institution” has the meaning given the term in section 509 of the Gramm-Leach-Bliley Act (15 U.S.C. 6809).

(3) Fraud protection data

The term “fraud protection data” means a combination of the following information with respect to an individual:

(A)

The name of the individual (including the first name and any family forename or surname of the individual).

(B)

The social security number of the individual.

(C)

The date of birth (including the month, day, and year) of the individual.

(4) Permitted entity

The term “permitted entity” means a financial institution or a service provider, subsidiary, affiliate, agent, subcontractor, or assignee of a financial institution.

(c) Efficiency
(1) Reliance on existing methods

The Commissioner shall evaluate the feasibility of making modifications to any database that is in existence as of May 24, 2018, or a similar resource such that the database or resource—

(A)

is reasonably designed to effectuate the purpose of this section; and

(B)

meets the requirements of subsection (d).

(2) Execution

The Commissioner shall make the modifications necessary to any database that is in existence as of May 24, 2018, or similar resource, or develop a database or similar resource, to effectuate the requirements described in paragraph (1).

(d) Protection of vulnerable consumers

The database or similar resource described in subsection (c) shall—

(1)

compare fraud protection data provided in an inquiry by a permitted entity against such information maintained by the Commissioner in order to confirm (or not confirm) the validity of the information provided;

(2)

be scalable and accommodate reasonably anticipated volumes of verification requests from permitted entities with commercially reasonable uptime and availability; and

(3)

allow permitted entities to submit—

(A)

1 or more individual requests electronically for real-time machine-to-machine (or similar functionality) accurate responses; and

(B)

multiple requests electronically, such as those provided in a batch format, for accurate electronic responses within a reasonable period of time from submission, not to exceed 24 hours.

(e) Certification required

Before providing confirmation of fraud protection data to a permitted entity, the Commissioner shall ensure that the Commissioner has a certification from the permitted entity that is dated not more than 2 years before the date on which that confirmation is provided that includes the following declarations:

(1)

The entity is a permitted entity.

(2)

The entity is in compliance with this section.

(3)

The entity is, and will remain, in compliance with its privacy and data security requirements, as described in title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), with respect to information the entity receives from the Commissioner pursuant to this section.

(4)

The entity will retain sufficient records to demonstrate its compliance with its certification and this section for a period of not less than 2 years.

(f) Consumer consent
(1) In general

Notwithstanding any other provision of law or regulation, a permitted entity may submit a request to the database or similar resource described in subsection (c) only—

(A)

pursuant to the written, including electronic, consent received by a permitted entity from the individual who is the subject of the request; and

(B)

in connection with a credit transaction or any circumstance described in section 1681b of title 15.

(2) Electronic consent requirements

For a permitted entity to use the consent of an individual received electronically pursuant to paragraph (1)(A), the permitted entity must obtain the individual’s electronic signature, as defined in section 7006 of title 15.

(3) Effectuating electronic consent

No provision of law or requirement, including section 552a of title 5, shall prevent the use of electronic consent for purposes of this subsection or for use in any other consent based verification under the discretion of the Commissioner.

(g) Compliance and enforcement
(1) Audits and monitoring

The Commissioner may—

(A)

conduct audits and monitoring to—

(i)

ensure proper use by permitted entities of the database or similar resource described in subsection (c); and

(ii)

deter fraud and misuse by permitted entities with respect to the database or similar resource described in subsection (c); and

(B)

terminate services for any permitted entity that prevents or refuses to allow the Commissioner to carry out the activities described in subparagraph (A).

(2) Enforcement
(A) In general

Notwithstanding any other provision of law, including the matter preceding paragraph (1) of section 505(a) of the Gramm-Leach-Bliley Act (15 U.S.C. 6805(a)), any violation of this section and any certification made under this section shall be enforced in accordance with paragraphs (1) through (7) of such section 505(a) by the agencies described in those paragraphs.

(B) Relevant information

Upon discovery by the Commissioner, pursuant to an audit described in paragraph (1), of any violation of this section or any certification made under this section, the Commissioner shall forward any relevant information pertaining to that violation to the appropriate agency described in subparagraph (A) for evaluation by the agency for purposes of enforcing this section.

(h) Recovery of costs
(1) In general
(A) In general

Amounts obligated to carry out this section shall be fully recovered from the users of the database or verification system by way of advances, reimbursements, user fees, or other recoveries as determined by the Commissioner. The funds recovered under this paragraph shall be deposited as an offsetting collection to the account providing appropriations for the Social Security Administration, to be used for the administration of this section without fiscal year limitation.

(B) Prices fixed by Commissioner

The Commissioner shall establish the amount to be paid by the users under this paragraph, including the costs of any services or work performed, such as any appropriate upgrades, maintenance, and associated direct and indirect administrative costs, in support of carrying out the purposes described in this section, by reimbursement or in advance as determined by the Commissioner. The amount of such prices shall be periodically adjusted by the Commissioner to ensure that amounts collected are sufficient to fully offset the cost of the administration of this section.

(2) Initial development

The Commissioner shall not begin development of a verification system to carry out this section until the Commissioner determines that amounts equal to at least 50 percent of program start-up costs have been collected under paragraph (1).

(3) Existing resources

The Commissioner may use funds designated for information technology modernization to carry out this section.

(4) Annual report

The Commissioner shall annually submit to the Committee on Ways and Means of the House of Representatives and the Committee on Finance of the Senate a report on the amount of indirect costs to the Social Security Administration arising as a result of the implementation of this section.

Source credit: (Pub. L. 115–174, title II, § 215, May 24, 2018, 132 Stat. 1323.)

history & why it existsrecord from the source credit
  • 2018Enacted · Pub. L. 115-174 · 132 Stat. 1323

A history note hasn’t been published yet. The record shows enactment by Pub. L. 115-174 on 2018-05-24.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case